Can You Put Customer Data in ChatGPT and Co.? The GDPR Rules
When can you enter customer data into ChatGPT, Copilot or Gemini? The GDPR rules on legal basis, purpose limitation, Article 9 and US transfers, explained simply.
Can you enter customer data into ChatGPT, Copilot or Gemini? The short answer: sometimes yes, often only under conditions, and sometimes clearly no. Three things decide it. Do you have a legal basis under Article 6 GDPR? Are you entering only the data you truly need? And do you have a data processing agreement (DPA) with the vendor? The safest lever stays the same: enter as little personal data as possible, and anonymize it first.
First the legal basis: Article 6 GDPR
Personal data is any information about an identifiable person: name, email, phone number, customer ID. The moment you process such data, you need a lawful ground. Article 6 GDPR lists them. Three matter most for companies. Without one of these grounds, entering the data into an AI tool is not allowed.
- Contract (Art. 6(1)(b)): the processing is needed to fulfil a contract with the customer.
- Legitimate interest (Art. 6(1)(f)): your interest prevails and the customer's rights are not harmed. A balancing test is required.
- Consent (Art. 6(1)(a)): the customer agreed freely and with full information. It must be revocable.
- Important: the legal basis must cover the specific use with an AI vendor, not just the original purpose of collecting the data.
Purpose limitation and data minimisation: only what is needed
Article 5 GDPR asks for two things often forgotten in daily AI use. Purpose limitation means data may only be used for the purpose you collected it for. Data minimisation means only as much data as truly needed. If you ask the AI to draft an offer, it rarely needs the company name and almost never the full customer name.
- 1Before every prompt, ask: does the AI really need this person to solve the task?
- 2Replace real names with placeholders when the context still works with a placeholder.
- 3Remove attachments, signatures and metadata that carry hidden personal data.
- 4Write down which data types are allowed for which task, and train the team on it.
Special categories: Article 9 GDPR
Some data is specially protected. Article 9 GDPR calls it special categories. It covers health data, ethnic origin, religion, political opinion, trade union membership, sex life and biometric data. For this data there is a general ban with narrow exceptions. As a rule, such data does not belong in a general AI tool.
- Baseline rule: processing is forbidden unless a narrow exception applies (e.g. explicit consent).
- Examples: a customer's sick note, a diagnosis, details on origin or religious beliefs.
- In practice: remove or replace this data before any AI use, do not try to balance it.
- Employee data protection also applies: for staff data, the works council may have a say (German BetrVG).
US vendors and third-country transfers
Many AI vendors sit in the US or process there. That is a third-country transfer and needs a basis under Chapter V GDPR. Since 2023 the EU-US Data Privacy Framework exists: transfers to certified companies are possible through it. Always check whether the specific vendor is certified, and read its current documentation.
- Check whether the vendor is listed under the EU-US Data Privacy Framework or uses Standard Contractual Clauses.
- Check where your inputs are stored and whether they are used for training. According to OpenAI, inputs via the API and business products are not used for training by default; free consumer versions may be handled differently. Check OpenAI's current documentation.
- The same applies to Microsoft Copilot and Google Gemini: enterprise offerings often have different rules than free versions. According to the vendors, storage and training differ by product.
- The safest way to lower transfer risk: do not send the vendor clear data at all.
Decision table: which data may go into the AI?
The table below sums up common cases. It is guidance, not a free pass. Check each case in your own context, because a single extra detail can change the assessment.
| Data type | Allowed? | Condition |
|---|---|---|
| Truly anonymous data (no link to a person) | Usually yes | Only if no one can be identified from it |
| A customer's name and email | Only with a basis | Legal basis under Art. 6 plus a DPA with the vendor |
| Customer lists in bulk | Critical | Check minimisation, better tokenize or aggregate |
| Health, origin, religion (Art. 9) | Usually no | Only with a narrow exception, e.g. explicit consent |
| Credentials, passwords, API keys | No | Never in prompts, regardless of the GDPR |
| Pseudonymized or tokenized values | Lower risk | Still personal data, but exposure drops sharply |
The lever: a DPA plus anonymizing before you send
Two measures cut the risk the most. First, a data processing agreement (DPA) under Article 28 GDPR: it sets out how the vendor may handle the data. Second, data minimisation at the source. If the AI never sees real clear data, there is less to protect. This is exactly where ONYRI Sanitize helps.
- Sign a DPA with every AI vendor before you process personal data.
- Anonymize prompts before sending: ONYRI detects sensitive data in the browser and replaces it with reversible tokens.
- The token-to-value mapping stays in the browser and never leaves it; only the already-anonymized text goes to the model.
- Stay honest: tokenization is pseudonymization. It reduces exposure and supports data minimisation, but it removes no obligations. Pseudonymized data stays personal data (GDPR Recital 26).
Frequently asked questions
- Can I enter customer names into ChatGPT?
- Only if you have a legal basis under Art. 6 GDPR and a DPA with the vendor. Often it is simpler and safer to replace the name with a placeholder. The task rarely needs the real name at all.
- Is the free version of ChatGPT enough for handling customer data?
- Often not. According to OpenAI, storage and training differ between free consumer versions and the API or business products. Check OpenAI's current documentation and whether a DPA is possible before entering personal data.
- Does anonymizing make my data exempt from the GDPR?
- No. Only truly anonymous data, where no one can be identified, falls outside the GDPR. Tokenization is pseudonymization: it lowers the risk, but the data stays personal (Recital 26).
- Do I need a DPA with the AI vendor?
- If the vendor processes personal data on your behalf, yes. Article 28 GDPR requires a data processing agreement. Without a DPA, you should not enter customer data in clear text.
Sources & references
- GDPR, full text (EUR-Lex) — Publications Office of the EU
- Guidance note on AI and data protection — German Data Protection Conference (DSK)
- German Federal Commissioner for Data Protection — BfDI
- EDPB guidelines, recommendations and best practices — European Data Protection Board (EDPB)
Keep your sensitive data in your browser
ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.